Fortra Patches Critical Vulnerabilities in BoKS
Fortra has released patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three critical flaws. These vulnerabilities include an authentication bypass due to predictable password generation, a command injection vulnerability allowing root shell command execution, and a stack buffer overflow causing memory corruption. The issues affect BoKS deployments managing Active Directory service accounts and components accessible over the network. No exploitation in the wild has been reported. The vendor has issued patches addressing these vulnerabilities.
AI Analysis
Technical Summary
Fortra patched eight vulnerabilities in BoKS, notably three critical ones: CVE-2026-79901 (CVSS 9.9) is an authentication bypass caused by predictable Active Directory service account passwords generated from a pseudo-random sequence seeded with the current Unix timestamp. An attacker knowing the service principal and approximate password-change time can reproduce and verify password candidates offline. CVE-2026-79898 (CVSS 9.1) is a command injection flaw in the crlserver component exploitable via BCC and WSI REST or SOAP APIs, allowing authenticated users to execute shell commands as root. CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in the autoregistration functionality enabling remote memory corruption. Additional high- and medium-severity issues include heap buffer overflows, out-of-bounds reads, insecure temporary file usage, and predictable password generation. No known active exploitation has been reported.
Potential Impact
Successful exploitation of these vulnerabilities could allow attackers to bypass authentication controls, execute arbitrary commands with root privileges, and cause memory corruption potentially leading to denial of service or code execution. The authentication bypass vulnerability could be exploited without administrative access if the attacker knows the service principal and timing information. The command injection vulnerability allows authenticated users to gain root shell access remotely. The memory corruption flaw could be triggered remotely, posing a risk of system compromise. These impacts are critical given BoKS's role in privileged access management.
Mitigation Recommendations
Fortra has released official patches addressing all identified vulnerabilities in BoKS. Organizations using BoKS should apply these patches promptly to remediate the critical authentication bypass, command injection, and memory corruption flaws. No mention of any vulnerabilities being exploited in the wild has been made, and the vendor recommends updating to the patched versions as the primary mitigation. No additional temporary workarounds or mitigations were specified.
Fortra Patches Critical Vulnerabilities in BoKS
Description
Fortra has released patches for eight vulnerabilities in its Core Privileged Access Manager (BoKS), including three critical flaws. These vulnerabilities include an authentication bypass due to predictable password generation, a command injection vulnerability allowing root shell command execution, and a stack buffer overflow causing memory corruption. The issues affect BoKS deployments managing Active Directory service accounts and components accessible over the network. No exploitation in the wild has been reported. The vendor has issued patches addressing these vulnerabilities.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Fortra patched eight vulnerabilities in BoKS, notably three critical ones: CVE-2026-79901 (CVSS 9.9) is an authentication bypass caused by predictable Active Directory service account passwords generated from a pseudo-random sequence seeded with the current Unix timestamp. An attacker knowing the service principal and approximate password-change time can reproduce and verify password candidates offline. CVE-2026-79898 (CVSS 9.1) is a command injection flaw in the crlserver component exploitable via BCC and WSI REST or SOAP APIs, allowing authenticated users to execute shell commands as root. CVE-2026-12627 (CVSS 9.8) is a stack buffer overflow in the autoregistration functionality enabling remote memory corruption. Additional high- and medium-severity issues include heap buffer overflows, out-of-bounds reads, insecure temporary file usage, and predictable password generation. No known active exploitation has been reported.
Potential Impact
Successful exploitation of these vulnerabilities could allow attackers to bypass authentication controls, execute arbitrary commands with root privileges, and cause memory corruption potentially leading to denial of service or code execution. The authentication bypass vulnerability could be exploited without administrative access if the attacker knows the service principal and timing information. The command injection vulnerability allows authenticated users to gain root shell access remotely. The memory corruption flaw could be triggered remotely, posing a risk of system compromise. These impacts are critical given BoKS's role in privileged access management.
Mitigation Recommendations
Fortra has released official patches addressing all identified vulnerabilities in BoKS. Organizations using BoKS should apply these patches promptly to remediate the critical authentication bypass, command injection, and memory corruption flaws. No mention of any vulnerabilities being exploited in the wild has been made, and the vendor recommends updating to the patched versions as the primary mitigation. No additional temporary workarounds or mitigations were specified.
Technical Details
- Classification
- {"confidence":0.9,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/","fetched":true,"fetchedAt":"2026-10-03T11:46:09.596Z","wordCount":1021}
Threat ID: 6ac0eb01a43b0b3b89bd928f
Added to database: 10/03/2026, 11:46:09 UTC
Last enriched: 10/03/2026, 11:46:14 UTC
Last updated: 10/03/2026, 20:00:40 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.